Author:Boaz Sobrado,Forbes
Compiled by: Shenchao TechFlow
Shenchao Guide: How far is quantum computing from truly breaking Bitcoin? This article breaks down the "$470 Billion Quantum Race": which coins are already at risk, why "exposed ≠ stolen", the timelines given by Google and the Ethereum Foundation, and the fierce debate over BIP-360 / BIP-361 regarding freezing dormant coins. Even more intriguing is the startups' head start—American Fortress claims "quantum resistance without migrating addresses", yet its paper is unpublished, its design unaudited. Is it cold fusion or another crypto narrative? The article offers a cautious judgment.
"That's the End of Bitcoin" — The $470 Billion Quantum Race
A quantum computer might be able to break the cryptography protecting millions of bitcoins. This article delves into the "freeze controversy", the $470 billion exposed to risk, and the startups racing to fix this vulnerability.
"I think Bitcoin is finished in four years," said David McAlvany, CEO of the gold app Vaulted, on the On The Margin podcast. "We will have quantum computing in four years, and that will be the end of Bitcoin. You can solve all the math problems instantly."
"I don't know if it's four years, five years, or two months," he added. As of mid-2026, a machine capable of this does not exist. But now this threat has a concrete timeline.
Attackers Realized This Sooner Than Security Teams
"It's a bit unfortunate that attackers realized this before infrastructure teams, before security teams," said Ido Sofer, founder of key management company Sodot, on the On The Margin podcast. "We are the first to face brand new attack vectors every time."
Galaxy Digital estimated in March 2026 that about 7 million bitcoins were in addresses where public keys had been exposed on-chain, worth approximately $470 billion. Glassnode's figure is 6.04 million, or 30.2% of the supply. Both are estimates, not protocol-level statistics; Galaxy called this risk "real, but far from an existential crisis". These exposed coins include Satoshi-era addresses that leaked their original public keys, and any addresses reused after their first spend. Exposure does not equal theft. It only becomes theft when a machine can reverse the math puzzle—and such a machine does not yet exist.
Bring Your Own Lock
"When you are on Bitcoin, Ethereum, Solana, currently you are locked into the one type of lock they allow you to use, just one," said Yoon Auh, CEO of BOLTS Technologies, on the podcast. "When you see quantum computing progress, those locks can be broken, and that is what they are afraid of."
These locks look increasingly fragile each year. Google researcher Craig Gidney proved in May 2025 that breaking RSA-2048 might require less than 1 million qubits, twenty times less than his own 2019 estimate. A Google whitepaper in April 2026 pushed the required qubit count for breaking Bitcoin's elliptic curve cryptography below 500,000. Ethereum Foundation researcher Justin Drake estimated that by 2032, the probability of a quantum computer cracking a Bitcoin private key from an exposed public key is around 10%. In April 2026, a researcher chasing Project Eleven's "Q-Day prize" cracked a 15-bit key on real quantum hardware. A real key is 256 bits, so this is just a toy—but a year ago, this toy didn't work at all.
Auh's solution is to give the choice of cryptography back to the user, not the chain. "Bring your own lock, choose your own lock," he said. BOLTS demonstrated its per-transaction cryptography scheme to NIST's post-quantum cryptographers and ran a quantum-resilient pilot on the Canton Network in December 2025. NIST finalized its first three post-quantum standards in August 2024.
Bitcoin developers themselves are divided on how to respond. A draft proposal, BIP-360 by Hunter Beast, would add a new quantum-resistant address type. Another, BIP-361 by Jameson Lopp and five co-authors, is chilling: it would phase out old-style signatures in two stages, and any coins never migrated (including those believed to belong to Satoshi) would become unspendable. Proponents argue that freezing dormant coins is better than letting future quantum thieves drain them and dump them on the market. Critics call it confiscation. Algorand has used quantum-resistant Falcon signatures for its state proofs since 2022; Quantum Resistant Ledger and the publicly listed BTQ are attacking the same problem from different angles.
Like Discovering Cold Fusion
Enter American Fortress among these players—an Austin-based company that completed an $8 million seed round in May, co-led by 0G Labs, SAVA Digital Asset Fund, and Moon Pursuit Capital. Formerly MatterFi, it claims to offer "quantum resistance across all chains without users needing to migrate any addresses", paired with a backward-compatible Bitcoin soft fork designed to automatically freeze vulnerable dormant wallets before attackers can strike. Its founder, Michal "Mehow" Pospieszalski, is not modest: "This quantum work is so good I couldn't give it away," he said on the On The Margin podcast about the quantum work. "It's like discovering cold fusion."
These claims warrant cautious scrutiny. "This algorithm is not news," Pospieszalski said. "People suggested long ago that you could generate additional proofs around existing addresses. But it was so slow that it was abandoned. We made it 100 times faster on a regular PC." American Fortress has patented a post-quantum transaction signature, but filing establishes priority, not proof; its technical paper is unpublished, and its design is not publicly audited. The company has deployed a beta version on Arbitrum, with a partner manager at Offchain Labs quoted expressing support—though that is one deployment, not a formal endorsement of the cryptography. "Post-quantum security is not a future feature, it's a necessity today," said 0G Labs CEO Michael Heinrich in the funding announcement.
Privacy Is Not Anonymity
The quantum work is only half its pitch. The other half is a compliance and privacy layer, built on the same argument: cryptocurrency has never truly proven who paid whom. "If I send you money, you get a cryptographic proof that it indeed came from my private key," Pospieszalski said. "That was completely impossible before." He points to "address poisoning"—scammers filling a victim's transaction history with look-alike addresses; in May 2024, one such attack drained $68 million in wrapped Bitcoin, though funds were later recovered. His fix is to attach proof of origin to each transaction and let users disclose identity only when they choose. "We don't require you to hold an ID to use the system," he said. "It's like ENS, just private."
Whether a privacy layer with built-in compliance is coherent is exactly what others in the industry are grappling with. "I have always viewed privacy and anonymity as completely different things," said Varun Kabra, Chief Growth Officer at Concordium, on the On The Margin podcast. Concordium uses zero-knowledge proofs to embed identity on-chain, so "because there is selective disclosure, there are zero-knowledge proofs, no one knows it's you". That is the same bet American Fortress is making. Kabra phrases the compliance line identically: "You control what you want to disclose, to whom, but subject to the law," he said. "No one should be above the law."
You Can't Prove It
Pospieszalski's belief that systems should be able to prove their own honesty predates cryptocurrency. The self-described white-hat hacker was CTO of the Election Science Institute around 2006, analyzing ES&S's iVotronic voting machines and warning they lacked cryptographic means to confirm whether a vote was counted once. "As a vote counter, you cannot prove to me that you counted my vote, didn't double-count it, or didn't under-count it," he said. "You can't prove it." Later, he did forensic work for the plaintiff's side in the disputed 2020 Antrim County, Michigan election case. According to his account, the anomalies there traced back to a misconfigured ballot definition file—consistent with an administrative explanation accepted by a bipartisan hand audit and all courts that heard the case; no fraud was proven before dismissal.
None of these funded fixes currently address a deeper concern for a long-term holder. McAlvany, whose business is selling gold, asks whether Bitcoin can last 5,000 years. "Gold, I'm pretty sure it will survive," he said. "Bitcoin, maybe not."








